Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ahmadhusain
New Contributor

I can't traceroute to fortigate firewall

Dear 

I can't traceroute to fortigate firewall from the any router and switch

but i can do from the windows computer 

i can also traceroute to device which is connected behind the fortigate firewall, only problem is coming when i try to to traceroute to fortigate device from Cisco router and switch

Please suggest 

Thanks  

5 REPLIES 5
ede_pfau
SuperUser
SuperUser

hi,

make sure you have enabled 'Ping' capability in the interface setup:

Network>Interfaces>WAN, Access, tick 'ping'.

If that is already the case:

check on the same page that you have not specified 'Trusted Hosts'. This will limit access not only for login but ping as well.


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
ahmadhusain
New Contributor

Thanks for you reply

I have already checked the ping on the interface panel but still same problem

my problem is when i try to ping or traceroute form the router it's showing me the timeout from the remote branch.But when i try to ping from any client computer OS "windows" it's working both can traceroute and ping from the remote site

Only problem coming with the router 

 

Please Help 

 

emnoc
Esteemed Contributor III

The problem has nothing todo witth fortigate allowaccess

 

Have you ran  cli-dm diag debug flow?  Have you  tried a icmp-traceroute ( most likely the default for the router is a UDP port based traceroute  )

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
neonbit
Valued Contributor

Do your adminstrators have trusted hosts configured?

 

If you run the following command from the Fortigate and then ping from the router, can you see the pings hitting the FortiGate and leaving it?

 

diag sniffer packet any 'icmp and host FORTIGATEIPADDRESS' 4

ahmadhusain
New Contributor

can you please clear little bit more 

i ran diag sniffer command on the fortigate but not able to understand on that it's showing me lot of ip's which's hitting to the interface on the fortigate 

i got the reply from the router to my pc on fortigate

27.590316 192.168.13.1 -> 192.168.14.87: icmp: echo reply But i was ping to fortigate but didn't get any information as like above 

 

Please assist if i'm doing something wrong  

 

 

thanks 

Labels
Top Kudoed Authors